riddle-quiz-maker

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated purpose, and the CLI comes from the official npm registry rather than an obviously rogue source. However, all authentication and Riddle Quiz Maker access are mediated through Membrane, a third-party platform, and the skill encourages dynamic action creation plus unpinned `@latest` CLI execution. This is not confirmed malware, but it carries meaningful trust and account-scope risk due to credential delegation, intermediary data flow, and the ability to perform live account actions.

Confidence: 84%Severity: 53%
Audit Metadata
Analyzed At
Apr 22, 2026, 11:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Friddle-quiz-maker%2F@2881bd3fc5e3c35a97230304500ecb19e8522ee0